Critical analysis of the Carmo- Jones system of Contrary- to- Duty obligations * 



Dov M Gabbay f 
King's College, London * 

Karl Schlechta § 
Laboratoire d'Informatique Fondamentale de Marseille ' 

February 17, 2010 



Abstract 



o 

This paper offers a technical analysis of the contrary to duty system proposed in Carmo- Jones. We offer analy- 
' sis/simplification/repair of their system and compare it with our own related system. 
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1 Introduction 

The present paper was inspired by the important paper !CJ02. j of J. Carmo and A.Jones on contrary-to-duties. 

In that paper Carmo and Jones present a logical system designed to solve many of the current puzzles of contrary-to-duties. They 
propose a system with the unary connective O(B) and the binary connective 0{B /A) and using these connectives give a detailed 
case analysis of several contrary-to-duty paradoxes. 

Gabbay, in his paper [Gab08] proposed a reactive Kripke semantics approach to contrary-to-duties and made use of the Carmo 
and Jones paper to draw upon examples and analysis. Gabbay promised in his paper an analysis of the Carmo- Jones approach 
and a comp arison w ith his own paper. Meanwhile Gabbay and Schlechta develope d the r eactive and hierarchical approach to 
conditionals [GS08d] as well as a general road map paper for preferential semantics [GS08c and armed with this new arsenal of 
methods (Carmo- Jones paper was written 10 years ago), we believe we can give a preferential analysis of the Carmo- Jones paper. 

Our comments are strictly mathematical. Our own philosophical approach is outlined in GS08g . 
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2 The Carmo-Jones system 



To model a contrary to duty set of sentences given in a natural language, which avoids paradoxes, we need a logic L and a 
translation from natural language into L. The translation must be such that whenever the original natural language set is coherent 
and consistent in our common sense reading of it, its natural formal translation in L is consistent in L (otherwise we get what is 
referred to as a paradox, relative to L). One such logic L is dyadic modal logic. We have a binary modal operator 0(B/A) reading 
B is obligatory relative to a given A, i.e., we have multiple unary modalities Oa dependent on A. 

Thus we have 

t \= 0(B/A) iff for all s such that tR(A)s holds we have that s\= B. 
It stands to reason that condition (5-b) below holds for R(A) , namely 
tR(A)s implies that s is in A (i.e., s \= A), 

We note that any correct logic L needs axioms for combining formulas of the form 
0{B/A) with 0(->B/(A A C)). 

Bearing all of the above in mind, let us examine the Carmo-Jones system. 

To fix our notation etc, the following is the Carmo-Jones system, regarded formally as a logical system with axioms and semantics 
as proposed by Carmo-Jones. (We take the liberty to change notation slightly, and will sometimes call the system CJ system.) 

Alphabet: 

classical propositional logic, with 5 additional modal operators: 

□ a with dual O a - the actually necessary /possible 

□ p with dual O p - the potentially necessary /possible 

0{./.) a dyadic deontic operator 

O a (.) monadic deontic operator: actual obligations 

O p (.) monadic deontic operator: potenial obligations 

Semantics: 

A model M = (W 7 av 7 pv 7 ob, V) where 
(1) 

(2) V an assignment function 

(3) av : W — > V(W) (the actually accessible worlds) such that 
(3-a) av(w) ^ 

(4) pv : W — > V(W) (the potentially accessible worlds) such that 
(4-a) av(w) C pv(w) 

(4-b) w G pv{w) 

(5) ob : V{W) -> V{V{W)) - the "morally good" sets 
such that for X, Y, Z C W 

(5-a) g ob{X) 

(5-b) iiYDX = ZDX, then Y G ob(X) Z G ob(X) 

(5-c) if Y, Z e ob(X), then Y n Z e ob(X) 

(5-d) if Y C A C Z, Y e ob(X), then (Z -X)UY e ob{Z) 

Remark: This results in a form of the Ross paradox: Let X := M( water plants), Y := M{ water plants and post letter), then 
(Z — X) U Y is the set of models where the plants are watered and the letter is posted (so far ok), or the plants are not watered. 
So either do both, or don't water the plants - which does not seem a good obligation. 

Validity in w is defined (for fixed M) inductively as follows (M{4>) is the set of points where <j) holds): 

w \= p :<^> w G V(p) 

the usual conditions for classical connectives 

w |= n a <f) av(w) C M(4>) 
w |= U p (j) :^ pv(w) C M{4>) 

w \= 0(4>/ip) :<^ M{4>) n M(tp) ^ and \JX{X C M(tp), X n M(<f>) ^ => M(<j>) e ob(X)) 
w h O a (j) M{4>) e ob(av(w)) and av(w) n M(-«f>) ^ 
w \= O p 4> :^> M(4>) G ob(pv(w)) and pu(ro) n M(-k/>) 7^ 
Axiomatics 

(A) □„ and D p 

(1) dp is a normal modal operator of type KT 

(2) U a is a normal modal operator of type KD 

(3) n p <f> -> d ^ 

(B) Characterisation of Of./-) 



(5) O(0/V>) A O(070) -> 0(0 A 07-0) 

(6) O(0/V>) 0(0/0 A V) 

(7) If h o -0', then h O(0/0) 4-> 0(0/0/) 

(8) If h V -> (0 o 0'), then h O(0/0) o 0(070) 

(C) Relationship between O(./0 and D p 

(9) O p O(0/0) -> DpO(0/0) 

(10) O p (0 A ■0' A 0) A 0(0/0) -> O(0/0 A 0') (5A2) 

(D) Characterization of a and O p 

(11) O a 0AO a 0^O a (0A0) 
OpcjyAOpip -> O P (0A0) 

(E) Relationships between O a (0 P ) and □„ (Q p ) 

(12) D a 0^ (-O a 0A-O a -0) 
□ p {-^0 p 4> A -iOp-10) 

(13) D a (0 ^ 0) -> (O a <-» O Q 0) 

□ p(0 O 0) -4 (O p O O p 0) 

(F) Relationships between 0(./.), O a (O p ) and D a (D p ) 

(14) 0(0/0) A D Q A O a A O Q -0 -> O Q 
0(0/0) A Dp0 A Op0 A Op-.0 -)■ Op0 

(15) 0(0/0) A O a (0 A 0) A O a (0 A -0) -> O a (0 -> 0) 
0(0/0) A Op(0 A 0) A Op(0 A -.0) ->■ Op(0 ->■ 0) 

2.1 General comments 

2.1.1 Methodological discussion 

We believe that Carmo and Jones important insight was that to solve contrary-to-duty and other Deontic paradoxes we need a 
wider family of operators capable of desc ribin g a wider context surrounding the problematic paradoxes. We agree with this view 
wholeheartedly. Gabbay's papers [Gab08] and |Gab08a] use reactive semantics to create such a context and the present paper will 
use hierarchical modality to create essentially the same context. See [Gab08j , Example 3.1. Also note that |Gab08j contains the 
following text (in the current January 2010 draft of the paper the text is on page 47): 

"We can now also understand better the approach of Carmo and Jones. Using our terminology, they were implicitly using the cut 
approach by translating into a richer language with more operators, including some dyadic ones." 

It would be useful to describe the methodology we use. 

Viewed formally, we have here a logical system CJ proposed by Carmo- Jones and a proposed semantics A4(CJ) for it, intended to 
be applied to the contrary-to-duties application area CTD. We want to study it and compare it with our own methodology, and 
technically simplify /assist /repair/support its formal details. 

We would like to provide preferential semantics for the Carmo Jones system. How can we do it? 
Let us list the methodological parameters involved. 

2.1.2 The semantics proposed must be compatible with the intended application. 

This means that the spirit of the semantics must correspond to the application. 

We explain by an example. Consider modal logic S4 and assume we are trying to apply it to the analysis of the tenses of natural 
language. 

The phrase "A is true from now on" can be modelled by DA. 

The phrase "John is reading now" i.e. the progressive tense can also be modelled as □( John is reading). 

Both examples give rise to modal S4. However the Kripke accessibility relation for S4 is the semantics suitable for the "from 
now on" linguistic construction, while the McKinsey-Tarski open intervals semantics for S4 is more suitable for the analysis of the 
progressive. (Sentences A are assigned intervals W(A) and DA is read as the topological interior of W(A).) 

Carmo- Jones indeed offer an analysis of the compatibility of their system in Section 6 of their paper. We will examine that. 

2.1.3 Soundness and completeness 

We ask whether the system is sound and complete for the semantics. (Carmo and Jones claimed only soundness.) If not, what 
axioms do we need to add to the system or what changes do we propose to the system to obtain correspondence? We will find that 
CJ is not complete for the proposed semantics. 



2.2 Discrepancies inside the CJ system 



(1) Unary obligations are dependent on accessibility relations av and pv, binary ones are not. As a consequence, unary obligations 
depend on the world we are in, binary ones do not. 

(2) Unary obligations must not be trivial, i.e. the contrary must be possible, binary ones can be trivial. 

(3) (And perhaps deepest) Binary obligations postulate additional properties of the basic choice function ob (which makes 
it essentially ranked), unary obligations need only basic properties (essentially corresponding to a not necessarily smooth 
preferential relation). This property is put into the validity condition, and not into rules as one would usually expect. 

(4) In the validity condition for 0{B/A) we have X C M(A) and X n M(B) 0, in the syntactic condition (SA2) we have 
0(A A B A C) A 0(C/B) V 0(C/A A B). These two coincide only if O is consistency - i.e. the underlying relation is the trivial 
universal one. 

(5) Semantic condition 5-d) gives essentially the condition for a preferential structure, an analogue on the syntactical side is 
missing - see Example 12.11 (pageH)) below, which shows that the axioms are not complete for the semantics. 

(6) We do not quite understand the derived obligation to kill and offer a cigarette. We think this should rather be: 0(^kill), 
0(-.o//er), 0(offer/kill). 

(7) P. 317, violation of 0(B/A), a better definition seems to be: 
m violates 0(B/A) iff in m holds: 

0-(0{B/A) A 0(A A B)) AAA ->B 
(O - is the inverse relation). 

In other words: in some antecedent, 0(B/A) was postulated, and A and B were possible, but now (i.e. in m)AA ->B holds. 
(We can strengthen: m \= D(A A -*B).) 

(8) We also think that temporal developments and intentions should better be coded explicitly, as implicit coding often leads to 
counterintuitive results. It is not our aim to treat such aspects here. 

2.3 Incompleteness of the CJ system 
Example 2.1 

Let C be defined by p, q, W := Mc be the set of its models. 
Let m 1 ^ p A q, m 2 ^ p A ~^q, M\ := {mi}, M 2 := {m 2 }. 
We write M(A) for the set of models of A. 

Set ob(Mi) := {M C M c : Mi C M}, ob(M 2 ) := {M C M c : M 2 C M}, ob(M) := for all other M. 

Let av(w) := pv(w) := W for all w £ W, i.e. both arc defined by wRw' for all w,w'. 

Thus, O a = O p , there is only one □, etc., and M \= w UA iff A is a tautology. 

M \= w OA will never hold, as av(w) = W, and ob(W) = 0. 

M \= w 0(B/A) is independent from w, so we write just M |= 0(B/A). 

Suppose M \= 0{B/A) holds, then M (A) n M{B) ^ 0, and thus M (B) E ob(M (A)). So A has to be (equivalent to) p A q or p A ~^q. 
But the only subsets of M(A) are then and M(A), and we have 0(<fi/p A q) iff h p A q — > <fi, and 0(<fi/p A -*q) iff h p A -*q — > <fi. 
No other 0{A/B) hold. 

We check the axioms (page 293-294) of |CJ02j : 
1-5 are trivial. 

6. is trivial, as M |= 0(B/A) implies hA^B. 

7. is trivial. 

8. Let 0(A/C), hC-^(A-> B), then hC^A, sohC-^B, so 0(B/C). 

9. trivial. 

10. If 0(C/B) and Con(A, B, C), then h B -> A, as B is complete, sohiABoB. 

11. is void. 

12. -13. trivial 

14. HO{B/A), then -.DA 

15. If 0{B/A), then h A -)• B, so 0(A A ->B) is impossible. 
Thus, our example satisfies the CJ axioms. 

If the system were to satisfy 5-d), then M(p) — {mi,m 2 } £ ob(M(j>)), and we would have 0(p/p) : 

First, M(p) n M(p) ^ 0. We then have to consider X = M(p), Mi, M 2 . But M(p) £ ob(Mi) n ob(M 2 ) n ofc(M(p)), thus 0(p/p) 
holds. 

□ 



2.4 Simplifications of the CJ system 



We make now some simplifications which will help us to understand the CJ system. 

(1) We assume the language is finite, thus we will not have any problems with non-definable model sets - see e.g. lGS08c| for an 
illustration of what can happen otherwise. 

(2) We assume that ob(X) C V(X). This is justified by the following fact, which follows immediately from the system of CJ, 
condition 5-b): 

Fact 2.1 

If A G ob(X), A C X, B C W-X, then A U B G ob(X). Conversely, if A G ob(X), then A n X G ob(X). 

Thus, what is outside X, does not matter, and we can concentrate on the inside of X. (Of course, the validity condition has then 
to be modified, M{B) G ob(X) will be replaced by: There is X' G ob(X), X' = M(B) n X. 

By 5-c), ob is closed under finite intersection, by overall finiteness, there is thus a smallest (by (C)) A G ob(X). We call this /x(X). 
Thus, fJ,(X) C X, which is condition (/x C). (If the language is not finite, we would have to work with the limit version. As we work 
with formulas only, this would not present a fundamental problem, see |Sch04j .) 

Let X C Z,Y := n(X), then by 5-d) {{Z - X) U Y) G ob(Z), so fj,(Z) C ((Z - X) U 7), or ^(Z) RIC /^(X), which is condition 
(fj,PR) - see below. 

We thus have that \x satisfies (jj, C) and (fj,PR), and we know that this suffices for a representation by preferential structures - see 
e.g. |Sch92j and Section (page 0} . 

Thus, the basic choice function ob is preferential for unary O. 

Note that C) + GuP-R) imply (fiOR) : n{X U Y) C /Lt(X) U ii(Y) - see lGS08cj and Section [5] (page . 

When we look now at the truth conditions for O a and Oi, we see that we first go to the accessible worlds - av(w) or pv(w) - and 
check whether fi(av(w)) C M (A) respectively /j,(pv(w)) C M(A) (and whether — u4 is possible). Thus, in preferential terms, whether 
av(w) |~ A, but au(u>) 1/ A. 

The case of 0(B/A) is a bit more complicated and is partly dissociated from O a and Oi. 

We said already above that 0(B/A) is independent from av and pt>, and from w. 

Second, and more importantly, the condition for 0(B/A) implies a converse of (fiOR) or (fj,PR) : 

(1) Setting X := M(A), we have fJ,{M(A)) C M(B), 

(2) as all sets are definable, we can choose -B s.t. /i(M(A)) = M(B), 

(3) for X C M(A), we have - using (2) - fi(X) C nlifln / 0- 
We thus have - if 0(B/A) holds - together with ((J.PR) that (ii =) holds, i.e. 

x cy, xn (i(Y) ^ m(x) = /i(r) n x. 

By 5-a) ju(JC) ^ 0, so (/z0) holds, too, and by |Sch04j . see also jGS08cj and Section [S] (page[7|), we know that such /i can be 
represented by a ranked smooth structure where all elements occur in one copy only. 

Thus, the basic choice function ob is ranked for binary 0(B/A). 

2.5 Suggested modifications of the CJ system 

(1) We assume finiteness (see above) 

(2) We work with the smallest element of ob(X) (see above) 

(3) We use only one accessibility relation (or operation) a. This is justified, as wc are mainly interested in formal properties here. 

(4) We make both O and 0(./ .) dependent on a. So validity of 0(./ .) depends on w, too. 
This eliminates one discrepancy between O and O (./.). 

(5) We allow both O and 0(./.) to be trivial. We could argue here philosophically, e.g.: if you are unable to kill your grandmother, 
should you then not any longer be obliged not to kill her? (No laws for jail inmates?) But we do this rather by laziness, to 
simplify the basic machinery. 

This eliminates a second discrepancy. 

(6) We take rankedness as a basic condition for ob, so it does not depend any more on validity of some 0(./ .). 

We can now describe the basic ingredients of our suggested system: 

(1) We take a finite ranked structure, together with - for simplicity - one additional relation of accessibility. 

(2) Binary and unary obligations will be represented the same way, i.e. the "best" situations will have lowest rank. 

(3) To correspond to the usual way of speaking in deontic logic, we translate this into a modal language, using techniques invented 
by Boutelier et al. 

(4) 



3 Our proposal for a modified CJ system 



The following is the proposed modified CJ system. 

3.1 Our system in a preferential framework 

Take any system for finite ranked structures. 

• A ranked structure is defined in Definition 15.41 (page l9| and Definition 15 . 71 (page [T2 |) . 

• Logical conditions are defined in Definition 15.31 (page 15)). 

• Take now a characterisation, see Proposition [5] (page [T3|) . 

• For definiteness, we choose (/U0), (fi =), (/U C). 

• We still have to add the accessibility relation R, which chooses subsets - this is trivial, as everything is definable. 

3.2 Our system in a modal framework 

The language of obligations has usually the flavour of modal languages, whereas the language describing preferential structures is 
usually different in decisive aspects. 

If we accept that the description of obligations is suitably given by ranked structures, then we have ready characterizations available. 
So our task will be to adapt them to fit reasonably well into a modal logic framework. We discuss this now. 

We will suppose that we have an entry point u into the structure, from which all models are visible through relation i?, with modal 
operators □ and O. R is supposed to be transitive. 

The first hurdle is to express minimality in modal terms. Boutilier and Lamarre have shown how to do it, see |Bou90a| and |Lam91) . 
(It was criticized in Mak93 , but this criticism does not concern our approach as we use different relations for accessibility and 
minimization.) 

We introduce a new modal operator working with the minimality relation, say we call the (irreflexive) relation R', and the 
corresponding operators □' and O'. Being a minimal model of a can now be expressed by m |= a A -iO'a. 

So a |~ j3 reads: u \= □((« A -iO'a) — > /3) - everywhere, if m is a minimal model of a, then /3 holds. 

(RatM) e.g. is translated to 



h □ ((0 A -nO'0) -» A A O (j> A -.OV A V') □ ((0 A ip' A -nO'(0 A ip')) ->■ ip 



The second hurdle is to handle subsets defined by accessibility from a given model m. In above example, all was done from u, with 
formulas. But we also have to make sure that we can handle expressions like "in all best models among those accessible from m 
<j> holds" . The set of all those accessible models corresponds to some <p m , and then we have to choose the best among them. In 
particular, we have to make sure that the axioms of our system hold not only for the models of some formulas seen from u, but 
also when those formulas are defined by the set of models accessible from some model to. 

Let R(m) := {n : mRn}, and n(X) be the minimal models of X. 

Suppose we want to say now: If mRm! (so R(m') C R(m) by transitivity), and R(m') n fj,(R(m)) ^ 0, then fj,(R(m')) = 
R(m!) H fJ,(R(m)). How can we express this with modal formulas? If we write to |= □</>, then we know that <p holds everywhere in 
R(m), but 4> might not be precise enough to describe R(m), e.g. <p might be TRUE. 

We introduce an auxiliary modal relation i?_ with operators □_ and 0_ s.t. mi?_m' iff not(mRm'). (If R is not reflexive, U_ will 
not be either, and we change the definition accordingly. - Our notation differs from the one of Boutilier, we chose it as we do not 
know how to create his symbols.) 

We can now characterize R(m) by <p m : m \= d<f> m A -iO_0 m - everywhere <p m holds, and at no point we cannot reach from m, <p m 
holds. We can now express that <fi holds in the minimal models of R(m) by 

to |= {U<p m A -iO_^ m ) A □(((/>,„ A -lOVm) -> </>)■ 

Finally, we can express e.g. (AND) 

a |~ 4>, a |~ 4>' a <f> A <f/ 

in the case where a is defined by some R(m) as follows: 

«H D ( ( D <Am A -.O_0 ro ) A n((<j, m A -lO'ipm) —»(/>) A n(((f> m A ->0'4> m ) -> (/)') -> 

□((0m A-.O'0 m ) -> <M</>') 



4 Comparison to other systems 

We point out here the main points of |CJ02j . |GS08d , . and the present article, which differentiate them from the others. 
• The Carmo-Jones article 



(3) It presents a descriptive semantics. 

(4) It puts the operators in the object language and uses a modal logic language, as usual in the held. 

• The article on .4— ranked semantics, |GS08d] : 

(1) It contains a relatively exhaustive semantics for the ideal cases in contrary-to-duty obligations. 

— The A— ranked semantics allows us to express that a whole hierarchy of obligations (if ... . possible, then . . . .; if 
not, but . . . ., then ....;....) is satisfied, i.e. the agent "does his best". This hierarchy is directly built into the 
semantics, which is a multi-layered, semi-ranked structure, which can also be re-used in other contexts. 

— The article contains a sound and complete characterization of the semantics with full proofs. 

— The language is that of usual nonmonotonic logics, i.e. rules are given in the met a- language. 

(2) Paradoxa like the Ross paradox are not treated at all, we only treat the ideal case, and not individual obligations. 

(3) The additional accessibility relation is added without changing the overall language to a modal flavour. 

• The article on the semantics of obligations, [GS08g : 

(1) In this article, we present a discussion of elementary properties a notion of derivation of obligations should have. 

(2) There, we are not at all concerned about more complicated situations, involving accessibility etc. 

(3) We also see rankedness somewhat sceptically there. 

• The present article 

(1) We work with a ranked structure describing ideal situations as usual. 

(2) We fully integrate the underlying logic for the ideal cases in a modal framework, using an idea by Boutelier and Lamarre, 
and extending it with a complementary relation to precisely characterize the successor sets. 

5 Definitions and proofs 

Definition 5.1 

(1) We use V to denote the power set operator, H{Xi : i 6 /} := {g : g : I — ^ {J{Xi : i 6 /}, Vi 6 I-g{i) £ Xi} is the general 
cartesian product, card(X) shall denote the cardinality of X, and V the set-theoretic universe we work in - the class of all 
sets. Given a set of pairs X, and a set X, we denote by X \ X :— {(x,i) € X : x € X}. When the context is clear, we will 
sometime simply write X for X \ X. (The intended use is for preferential structures, where x will be a point (intention: a 
classical propositional model), and i an index, permitting copies of logically identical points.) 

(2) A C B will denote that A is a subset of B or equal to B, and A C B that A is a proper subset of B, likewise for A D B and 
Ad B. 

Given some fixed set U we work in, and X C U, then C(X) := U — X . 

(3) If y C V(X) for some X, we say that y satisfies 
(n) iff it is closed under finite intersections, 

(P|) iff it is closed under arbitrary intersections, 
(U) iff it is closed under finite unions, 
(U) iff it is closed under arbitrary unions, 
(C) iff it is closed under complementation, 
(— ) iff it is closed under set difference. 

(4) We will sometimes write A = B || C for: A = B, or A = C, or A = B U C. 
We make ample and tacit use of the Axiom of Choice. 



Definition 5.2 

(1) We work here in a classical propositional language C, a theory T will be an arbitrary set of formulas. Formulas will often be 
named 0, ip, etc., theories T, S, etc. 

v(C) will be the set of propositional variables of C. 
F(C) will be the set of formulas of C. 

Mr will be the set of ('classical! models for L. M(T) or Mt is the set of models of T. likewise M(6) for a, formula, 6. 



(2) Dc '■= {M(T) : T a theory in £}, the set of definable model sets. 

Note that, in classical propositional logic, %,Mc G D c, Dc contains singletons, is closed under arbitrary intersections and 
finite unions. 

An operation / : y — > V(Mc) for y C V(M£) is called definability preserving , (dp) or (udp) in short, iff for all X G DcC^y 
f(X)GD c . 

We will also use ((J-dp) for binary functions / : y x y — > V(Mc) - as needed for theory revision - with the obvious meaning. 

(3) h will be classical derivability, and 

T :={(/)■. T \- </>}, the closure of T under h . 

(4) Con(.) will stand for classical consistency, so Con((j>) will mean that 4> is classical consistent, likewise for Con(T). Con(T,T') 
will stand for Con(T U T'), etc. 

(5) Given a consequence relation |~, we define 
T := {0 : T |~ 0}. 

(There is no fear of confusion with T, as it just is not useful to close twice under classical logic.) 

(6) T V T' := V 4>' : 4> G T, ft G T'}. 

(7) If X C M £ , then Th(X) := {<p : X |= </>}, likewise for Th(m) , m G M £ . (|= will usually be classical validity.) 



Definition 5.3 

We introduce here formally a list of properties of set functions on the algebraic side, and their corresponding logical rules on the 
other side. Putting them in parallel facilitates orientation, especially when considering representation problems. 

We show, wherever adequate, in parallel the formula version in the left column, the theory version in the middle column, and the 
semantical or algebraic counterpart in the right column. The algebraic counterpart gives conditions for a function f : y —> V(U), 
where U is some set, and y C V(U). 

The development in two directions, vertically with often increasing strength, horizontally connecting proof theory with semantics 
motivates the presentation in a table. The table is split in two, as one table would be too big to print. The first table contains the 
basic rules, the second one those about cumulativity and rationality. 

Precise connections between the columns are given in Proposition [52] (page 

When the formula version is not commonly used, we omit it, as we normally work only with the theory version. 

A and B in the right hand side column stand for M(<f>) for some formula </>, whereas X, Y stand for M(T) for some theory T. 

• (PR) is also called infinite conditionalization We choose this name for its central role for preferential structures (PR) or 
(uPR). 

• The system of rules (AND) (OR) (LLE) (RW) (SC) (CP) (CM) (CUM) is also called system P (for preferential). Adding 
(RatM) gives the system R (for rationality or rankedness). 

Roughly: Smooth preferential structures generate logics satisfying system P, while ranked structures generate logics satisfying 
system R. 

• A logic satisfying (REF), (ResM), and (CUT) is called a consequence relation. 

• (LLE) and(CCL) will hold automatically, whenever we work with model sets. 

• (AND) is obviously closely related to filters, and corresponds to closure under finite intersections. (RW) corresponds to 
upward closure of filters. 

More precisely, validity of both depend on the definition, and the direction we consider. 

Given / and (u C), f(X) C X generates a principal filter: {X' C X : f(X) C X'}, with the definition: If X = M (T) , then 
T |~ iff f(X) C M((j>). Validity of (AND) and (RW) are then trivial. 

Conversely, we can define for X = M(T) 

X :={X' CX: 3<j)(X' = X n M(<j>) and T |- <£)}. 

(AND) then makes X closed under finite intersections, and (RW) makes X upward closed. This is in the infinite case usually 
not yet a filter, as not all subsets of X need to be definable this way. In this case, we complete X by adding all X" such that 
there is X' C X" CX, X' G X. 

Alternatively, we can define 

X :={X' CX: [\{X n M(4>) :T \^(j)}C X'}. 

• (SC) corresponds to the choice of a subset. 

• (CP) is somewhat delicate, as it presupposes that the chosen model set is non-empty. This might fail in the presence of ever 
better choices, without ideal ones; the problem is addressed by the limit versions. 



Tabic 1: Basic logical and semantic laws 



Basics 


{AND) 
<p |~ ip, <p ip 

cp (~ ip A ip' 


(AJvD) 
T |~ ip, T (~ V' => 
T WAf 


Closure under 
finite 
intersection 


/nn\ 

<p |~ 0' ~ "0 =^ 

<P v cp' ip 


T777T\ 

(OR) 
T n T' C T V T' 


f(xuv) c /(x)u/(y) 


|~ ip, <p h V =^ 

<f> v <P ip 


?7777777T 

T n T' C T V T' 


f(xuv) c p)uy 


(disjOR) 

(p 1 10 , |~ 01 

|~ t/j =^ <p v <?/ |~ ^ 


(disjOR) 
-nCon(T U T') => 
T n T' CTVT' 


(lidisjOR.) 
/(XuY) C f(X)Uf(Y) 


(LLE) 

Left Logical Equivalence 

h <-> 0' ' , ~ i/j 
0' |~ ip 


(LLE) 


trivially true 


(RW) Right Weakening 

|~ Ip, \~ ijj — ► Ip' =^ 
(p |~ Ip 


(W) 

T |~ h V' -> V>' 
T |~ V' 


upward closure 


(CCL) Classical Closure 


(6 J 6"L) 

T is classically 
closed 


trivially true 


(SC) Supraclassicality 

(p h ip => (p ip 


(SC) 
T C T 


(m c) 

/(X) C X 


(R.EF) KcHcxivity 
T U {a} f~ a 


\^ 1 ) 

Consistency Preservation 

(p \» j_ h _i_ 


(CP) 

T[vl4TH 


f(X) = =>. X = 






(p0/in) 
X ^ =s. /(X) ^ 
for finite X 






x c y => 
/(F) n x c /(X) 


rp A <p' C <f> U {<£'} 


T U T' C T U T' 


/(X)nY c pnY) 


(6"t/T) 

T [~ a; T U {a} |~ /9 =4- 
T h/3 


(CUT) 

T C T 7 C T =!> 
T> C T 


/(X) C Y C X =► 

/(X) c /(y) 



• (CUM) (whose more interesting half in our context is (CM)) may best be seen as normal use of lemmas: We have worked 
hard and found some lemmas. Now we can take a rest, and come back again with our new lemmas. Adding them to the 
axioms will neither add new theorems, nor prevent old ones to hold. (This is, of course, a meta-level argument concerning an 
object level rule. But also object level rules should - at least generally - have an intuitive justification, which will then come 
from a meta-level argument.) 



Fact 5.1 

The following table is to be read as follows: If the left hand side holds for some function / : y — > V(U), and the auxiliary properties 
noted in the middle also hold for / or y, then the right hand side will hold, too - and conversely. 

"sing." will stand for: "y contains singletons" 



Proposition 5.2 

The following table "Logical and algebraic rules" is to be read as follows: 

Let a logic (~ satisfy (LLE) and (CCL), and define a function / : D c -> D c by f(M(Tj) := M(T). Then / is well defined, 
satisfies (jidp), and T = Th(f(M(T))). 

If |~ satisfies a rule in the left hand side, then - provided the additional properties noted in the middle for => hold, too - / will 
satisfy the property in the right hand side. 

Conversely, if / : y ->• T(M C ) is a function, with D c C y, and we define a logic |~ by T := Th(f(M (T))), then (~ satisfies (LLE) 
and (CCL). If / satisfies (jjidp), then f(M (T)) = M(T). 

If / satisfies a property in the right hand side, then - provided the additional properties noted in the middle for <= hold, too - |~ 
will satisfy the property in the left hand side. 

If "T = </>" is noted in the table, this means that, if one of the theories (the one named the same way in Definition 15.31 fpagelS])') is 
equivalent to a formula, we do not need (jjdp). 



Table 2: Cumulativity and Rationality 



Cumulativity 


(CM) Cautious Monotony 

|~ i/j, ~ tp' 
A -0 K V*' 


(CM) 
T C T 7 C T 
T C T 7 


(/jC'M ) 
/(X) C Y C X => 
/(F) C UX) 


or (HesM ) 
Restricted Monotony 
T |~ a, /3 => T U {a} |~ /3 


(HHesM ) 
/(X) C A n B 
/(X n A) C B 


{CUM) Cumulativity 

~ V 
(</> |~ v' a V> h V>') 


(6'[7M) 
T C T 7 C T 


[ixCUM) 
f(X) C Y C X 
/(Y) = /(X) 




- 

T C T', T' C T 
T 7 = T 


/(X) C Y, /(F) c X 
/(X) = /(Y) 


Rationality 


(KatM) Rational Monotony 

~ l/>, => 

A -0' ~ V* 


(HatM) 
ConiTuT 7 ), T h T' => 
TDfuT 


(fj,HatM) 
X C Y, X n /(Y) # => 

/(X) c /(Y)nx 




(HatM = ) 
Con(l Ui J, J r J 
T = PUT 


(M =) 
/(x) = /(Y)nx 




(Log=') 
Con(T' U T) => 
TuT' = T'UT 


(p =') 
/(Y) nx/«4 

/(Ynx) =/(Y)nx 




(^09 II) 
T V T 1 is one of 

T, or T 7 , or T n T 7 
(by (CCL)) 


(f II) 

/(X U Y) is one of 
/(X), /(Y) or/(X)U/(Y) 




(-LogU) 

ConO? 7 U T), ^ContJ 7 U T) 
^Con(T VT'U T') 


( M U) 

/(Y) n (x - /(X)) # => 

/(X U Y) n Y = 




_ (Lo fl U') _ 
Con(T' U T), -.C£m(T' U T) 
=>TVT' = T 


(M-O 

/(Y) n (x - /(X)) ^ => 

/(XUY) = /(X) 






a 6 X - /(X) => 
36 G X.a f({a,b}) 



Fix £7^0, and consider arbitrary X. Note that this X has not necessarily anything to do with U, or U below. Thus, the functions 
/iM below are in principle functions from V to V - where V is the set theoretical universe we work in. 

Note that we work here often with copies of elements (or models). In other areas of logic, most authors work with valuation 
functions. Both definitions - copies or valuation functions - are equivalent, a copy (x, i) can be seen as a state (x, i) with valuation 
x. In the beginning of research on preferential structures, the notion of copies was widely used, whereas e.g., [KLM90] used that of 
valuation functions. There is perhaps a weak justification of the former terminology. In modal logic, even if two states have the 
same valid classical formulas, they might still be distinguishable by their valid modal formulas. But this depends on the fact that 
modality is in the object language. In most work on preferential stuctures, the consequence relation is outside the object language, 
so different states with same valuation are in a stronger sense copies of each other. 

(1) Preferential models or structures. 

(1.1) The version without copies: 

A pair M := (U, -<) with U an arbitrary set, and -< an arbitrary binary relation on U is called a preferential model or 
structure. 

(1.2) The version with copies : 

A pair M := (U, -<) with U an arbitrary set of pairs, and -< an arbitrary binary relation on U is called a preferential 
model or structure. 

If (x, i) 6 U, then x is intended to be an element of U, and i the index of the copy. 

We sometimes also need copies of the relation -< . We will then replace -< by one or several arrows a attacking non- 
minimal elements, e.g., x -< y will be written a : x — >• y , (x, i) -< {y, i) will be written a : (x, i) — > (y, i) , and finally we 
might have (a,k) : x — >• y and (a, k) : (x, i) — > (y, i) , etc. 

(2) Minimal elements, the functions um 

(2.1) The version without copies: 
Let M := (U, -<), and define 

u M (X) := {x e X : x E U A -.3a;' eln U.x' -< x}. 

um{X) is called the set of minimal elements of X (in M). 

Thus, um{X) is the set of elements such that there is no smaller one in X. 

(2.2) The version with copies: 

Let M := (U, -<) be as above. Define 

u M (X) := {x e X : 3(x,i) & U.^3(x',i') £ lA(x' e X A (x',i')' ■< (x,i))}. 

Thus, hm{X) is the projection on the first coordinate of the set of elements such that there is no smaller one in X. 

Again, by abuse of language, we say that um (X) is the set of minimal elements of X in the structure. If the context 
is clear, we will also write just u. 



.Basics 


i.i) 




=> (n) + (pC) 


( M PP') 


(1.2) 




(2.1) 


(»PR) 




(pOrt) 


(2.2) 


<=(cy + (-) 


(2.3) 


=> (m U 


(pwUR) 


(2.4) 


<= (m<=) + (-) 








(»PR) 




(fiCUT) 




ft 




(p C) + ( M CD) + (jj,CU M) 
+(pRatM) + (n) 




(pPR) 


(Jumulativity 


(5.1) 


(fiG'M) 


=> (nj + ^C) 


(pResM) 


(b.2) 


•«= (mtin.) 




e 




(juC'M) + (pCUT) 




(pCUM) 












(HCUM) 








(M C) + (pCUM) + (n) 




(p CD) 








(m c) + ( m 6"(;jw) 




(M<==>) 


nationality 




(pRatM) + (pPR) 


=> 


(M =) 


(11) 


<M =) 


=> 


(pPR) 


+ (pRatM) 


(12.1) 


(M =) 


=> (n) + ( P C) 


(P =') 


(12.2, 




(13) 


(cg + lc =) 


=> (u) 


(,uU) 


(14) 


( M C) + ( M 0) + (p =) 


=> (u) 


II), MU'), 


(pCUM) 


(15) 


(|iC)+((i II) 


=> (-) of y 


<M = 


) 


(IB) 


(m II) + (m e) + (^«)+ 

(M £) 


(U) + sing. 


(P =) 


4 


17 


1- 


(pCU M) + ( M = ) 


=> (U) + sing. 




\i e 


) 




18 




(pCUM) + (m — ) + (P C) 


=> (U) 




Mil 




( 


19 


) 


(,uPK) + (pCUM) + (p\\) 


==> sufficient, 
e.g., true in 


(*•=)■ 


(20) 


(p C) + (^PW) + (p =) 




(f II) 


(21) 


( M L)+(^) + (P II) 


5*- (without (-)) 


(f =) 


(22) 


(fy + ^Jii + if ||)+ 

(M =) + (juU) 


7^ 


(/* e) 

(thus not 
rcprcscntablc by 
ranked structures) 



Table 3: Interdepcndcncics of algebraic rules 



Table 4: Logical and algebraic rules 



Basics 


i.i 


(OR) 


=> 


(pOR) 


(1.2) 


<= 


(2.1) 


(disjOR) 


=> 


(pdisjOR) 


(2.2) 


<= 


(3.1) 


(wOR) 


=> 


(fiwOR) 




4= 


ffl- 


(SC) 


=> 




(4.2) 


<= 


(5.1) 


{CP) 


=> 




(5.2) 


4= 


(6.1) 


(PR) 


=> 


( P PP) 


(6.2) 


•«= (Mrfp) + (M <=) 


(6.S) 




(0.4) 


<= (m y 

T = <\> 


(6.5) 


(PR) 


T' = 4> 




(7.1) 


(CUT) 


=> 


(jxCUT) 


(7.2) 


4= 


(Jumulativity 


(8.1) 


(CM) 


=> 


(pCM) 




<^ 




(ResM) 


=► 


(pResM) 


(9.2) 


<^ 


(10.1) 


(<==>) 


=> 




iio.a 


<^ 


n.i 


(CUM) 


=> 


(HCUM) 


n.a 


<^ 


Rationality 


(12.1) 


(RatM) 


=► 


(pRatM) 




■«= (/idp) 


(ia.3 




(12\4) 


<^ 
T = 


(13.1) 


(RatM =) 


=► 


(H =) 


(13.i2 


<= IM^PJ 


(13.3) 


^ — (pdp) 


(13.4) 


<= 
T = <t> 


(14.1) 


(Log =') 


=> 


(P=) 


(14.i2 


<= (pdp) 


(14.3) 


1= -[pdp) 




<= T = <t> 


ffl 


(Log ||) 


=> 


(m II) 


(15.2) 




(16.1) 


(LogU) 


^(cy + (m =) 


(juU) 


(16.!2 




(16.3) 


5f= -(MdP) 


(17.1) 


(LogW) 


(A» £) + =) 


(MU') 


(17.2J 


<= (M d P) 


(17.3) 


1= -(Mdp) 



A4 is also called injective or 1-copy , iff there is always at most one copy {x, i) for each x. Note that the existence of 
copies corresponds to a non- injective labelling function - as is often used in nonclassical logic, e.g., modal logic. 

We say that M. is transitive, irreflexive, etc., iff -< is. 
Note that u(X) might well be empty, even if A is not. 



Definition 5.5 

We define the consequence relation of a preferential structure for a given prepositional language C. 

(1) (1.1) If m is a classical model of a language C, we say by abuse of language 

(to, i) (= 4> iff m \= 4>i 

and if X is a set of such pairs, that 

X \= <j) iff for all (to, i) G X m \= <j). 

(1.2) If M. is a preferential structure, and X is a set of L— models for a classical propositional language L, or a set of pairs 
(m,i), where the to are such models, we call M a classical preferential structure or model. 

(2) Validity in a preferential structure, or the semantical consequence relation defined by such a structure: 
Let M. be as above. 

We define: 

T \=m 4> iff u M (M(T)) h i.e., u M (M(T)) C Af(0). 

(3) will be called definability preserving iff for all X G £>£ /^(A) £ 

As fiM is defined on D £, but need by no means always result in some new definable set, this is (and reveals itself as a quite strong) 
additional property. 



Definition 5.6 

Let y C V(U). (In applications to logic, y will be £>£.) 

A preferential structure M. is called y— smooth iff for every X G y every element x G X is either minimal in X or above an element, 
which is minimal in X. More precisely: 

(1) The version without copies: 

If x G X G y, then either x G u(X) or there is x' G u(X).x' -< .x. 

(2) The version with copies: 

If a; G A G and (x,i) G W, then either there is no (x',i') G U, x' G A, (x',i') -< (x,i) or there is (x',i') G (x',i') -< (x,i), 
x 1 G A, s.t. there is no (x",i") G U, x" G A, with (x",i") -< (x',i'). 

(Writing down all details here again might make it easier to read applications of the definition later on.) 

When considering the models of a language £, A4 will be called smooth iff it is Dc~ smooth ; Dc is the default. 
Obviously, the richer the set y is, the stronger the condition y— smoothness will be. 



Fact 5.3 

Let -< be an irreflexive, binary relation on A, then the following two conditions are equivalent: 

(1) There is Q. and an irreflexive, total, binary relation -<' on ft and a function / : X — > Q, s.t. x -< y <^ f(x) -<' f(y) for all 
x,y G A. 

(2) Let x, y, z G A and x_Ly wrt. -< (i.e., neither x -< y nor y -< x), then z -< x z -< y and x -< z y -< z. 



Definition 5.7 

We call an irreflexive, binary relation -< on A, which satisfies (1) (equivalently (2)) of Fact 15.31 (page [12]) , ranked . By abuse of 
language, we also call a preferential structure (A, -<) ranked, iff -< is. 



Fact 5.4 

If ^ on A is ranked, and free of cycles, then -< is transitive. 



Proof 

Let x -< y -< z. If xJ-z, then y > z, resulting in a cycle of length 2. If z -< x, then we have a cycle of length 3. So x -< z. □ 



Remark 5.5 

Note that (fi =') is very close to (RatM) : (RatM) says: a ^ /3, a \/> -q a A 7 (~ Or, /(A) C B, f(A) nC/N 
/(A flC)CB for all A, B, C. This is not quite, but almost: f(A n C) C /(A) n C (it depends how many B there are, if f(A) is 
some such B, the fit is perfect). 



Fact 5.6 

In all ranked structures, (/i C), (/z =), (fiPR), (/z ='), (/z |j), (/iU), (/iU'), (/x g), (fiRatAl) will hold, if the corresponding closure 
conditions are satisfied. 



Proof 

(/1 C) and (uPR) hold in all preferential structures, 
(/i =) and (/i =') are trivial. 

(/UU) and (/xU') : All minimal copies of elements in f(Y) have the same rank. If some y G /(V) has all its minimal copies killed by 
an clement x G X, by rankcdness, a; kills the rest, too. 

(fi G) : If f({a}) = 0, we are done. Take the minimal copies of a in {a}, they are all killed by one element in X. 

(/i ||) : Case f(X) = : If below every copy of y G Y there is a copy of some x E X, then /(XU7) = 0. Otherwise f(XUY) = f(Y). 
Suppose now f(X) ^ 0, f(Y) ^ 0, then the minimal ranks decide: if they are equal, f(X U Y) = f(X) U f(Y), etc. 

(fiRatM) : Let X C Y, y £ X Ci f(Y) ^ 0, a; G f(X). By rankedness, y -< a;, or y_Lx, y -< x is impossible, as y G X, so y-Lx, and 

x g /(y). 
□ 



The following table summarizes representation by preferential structures. 

"singletons" means that the domain must contain all singletons, "1 copy" or "> 1 copy" means that the structure may contain 
only 1 copy for each point, or several, "(/x0)" etc. for the preferential structure mean that the fi— function of the structure has to 
satisfy this property. 

Note that the following table is one (the more difficult) half of a full representation result for preferential structures. It shows 
equivalence between certain abstract conditions for model choice functions and certain preferential structures. The other half - 
equ ivalence between certain logical rul es an d certain abstract conditions for model choice functions - are summarized in Definition 
15.31 (page [5J and shown in Proposition 15.21 (page |HJ) . 



Definition 5.8 

Let Z = {X , -<) be a preferential structure. Call Z 1 — 00 over Z, iff for all x G Z there are exactly one or infinitely many copies 
of x, i.e., for all x G Z {u G X : u — (x, i) for some 1} has cardinality 1 or > uj. 



Lemma 5.7 

Let Z = (X, -<) be a preferential structure and / : y — > V(Z) with y C V(Z) be represented by Z, i.e., for XeJ f(X) — fiz(X), 
and Z be ranked and free of cycles. Then there is a structure Z', 1 — 00 over Z, ranked and free of cycles, which also represents /. 



Proof 

We construct Z' = IX'. -<'). 



Table 5: Preferential representation 



^ i -+- 

ilD 



5 =* 



?++ 



+ + 

o 



^0" 



J. 

f sr. 
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- - .:- 
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a + 
ji 



+ 

'I 
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+ 
a, 

% 
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us- 
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let B := {x G zT: there is some (x,i) G A", s.t. for no (a;, j) £ A" {x,j) -< (x,z)}, 
let C := {a; £ Z: there is no (x, i) G X}. 

Let Ci : ? < k be an enumeration of C. We introduce for each such a w many copies (cj, n) : n < uj into A?', put all (cj, n) above all 
elements in X, and order the (ci,n) by (cj,rz) -<' (cj',n') :<^> (i = i' and n > n') or i > i'. Thus, all (ci,n) are comparable. 

If a 6 A, then there are infinitely many copies of a in X, as X was cycle-free, we put them all into X' . If b G £?, we choose exactly 
one such minimal element (6, m) (i.e., there is no (6, n) ~< (b, m)) into X' , and omit all other elements. (For definiteness, assume in 
all applications m = 0.) For all elements from A and B, we take the restriction of the order -< of X. This is the new structure Z 1 . 

Obviously, adding the (cj,n) does not introduce cycles, irreflexivity and rankedness are preserved. Moreover, any substructure of 
a cycle-free, irrefiexive, ranked structure also has these properties, so Z' is 1 — oo over Z, ranked and free of cycles. 

We show that Z and Z 1 are equivalent. Let then X C Z 1 we have to prove p(X) — p'(X) (p := pz, p' := pz 1 )- 

Let z G X — p(X). If z G C or z G A, then z p'(X). li z G B, let {z,m) be the chosen element. As z ^ p(X), there is x G X 
s.t. some (x,j) -< (z,m). x cannot be in C. If x G A, then also (x,j) -<' (z,m). If x G B, then there is some (x, fc) also in X' . 
(x,j) -< (x, k) is impossible. If (x, k) -< (x,j), then {z,m) >- (x, fc) by transitivity. If (x, fc)_L(x, j), then also (z,m) >- (x, fc) by 
rankedness. In any case, (z,m) >-' (x, fc), and thus z €" p'(X). 

Let z G — p'(X). If z G C or z G A, then z g" p(X). Let z G -B, and some (x,j) -<' (z,m). x cannot be in C, as they were 
sorted on top, so (x,j) exists in A too and (x,j) -< (z,m). But if any other (z,i) is also minimal in 2 among the (z,fc), then by 
rankedness also (x,j) -< (z,i), as (z, i)_L(z, m), so z g" p(X). □ 



We give a generalized abstract nonsense result, taken from [LMB01J . which must be part of the folklore: 
Lemma 5.8 

Given a set X and a binary relation R on X, there exists a total preorder (i.e., a total, reflexive, transitive relation) S on X that 
extends R such that 

Vx, y G X(xSy, ySx =>■ xR*y) 

where R* is the reflexive and transitive closure of R. 



Proof 



is a partial order. Let < be any total order on these equivalence classes that extends ^ . Define xSy iff [x] < [y]. The relation S is 
total (since < is total) and transitive (since < is transitive) and is therefore a total preorder. It extends R by the definition of < 
and the fact that < extends ^ . Suppose now xSy and ySx. We have [x] < [y] and [y] < [x] and therefore [x] = [y] by antisymmetry. 
Therefore x = y and xR*y. □ 



Proposition 5.9 

Let y C V(U) be closed under finite unions. Then (fi C), (/U0), (/i =) characterize ranked structures for which for all X G y X ^ 
=>■ H<{X) ^ hold, i.e., (jj, C), (//0), (/U =) hold in such structures for /i<, and if they hold for some //, we can find a ranked 
relation < on U s.t. /i = /i<. Moreover, the structure can be choosen y— smooth. 



Proof 

Completeness: 

Note that by Fact O (page 0) (3) + (4) (p ||), (/xU), (/iU') hold. 

Define aRb iff G y(a G /i(^4), & G A) or a = b. R is reflexive and transitive: Suppose aRb, bRc, let a G n{A), b G A, b G n(B), 
ceB.We show a G //(AuB). By (/i ||) a G /i(A U B) or 6 G fx(AUB). Suppose b G /j(ylUB), then fj,(A U 5) n A ^ 0, so by (p =) 
fi(A U B) f] A — ij,(A), so a G /j,(A U B). 

Moreover, a G 6 G A - ^(A) =4> -^(bRa) : Suppose there is B s.t. 6 G (J.(B), a e B. Then by (/xU) fi(A UB)nB = 8, and by 

(^U') n(A U B) = fi(A), but a G n(A) n B, contradiction. 

Let by Lemma [5T51 (page [T4l S* be a total, transitive, reflexive relation on U which extends R s.t. xSy, ySx xRy (recall that R 
is transitive and reflexive). Define a < b iff aSb, but not bSa. If a_L6 (i.e., neither a < b nor & < a), then, by totality of S 1 , aSb and 
bSa. < is ranked: If c < a_L6, then by transitivity of S cSb, but if bSc, then again by transitivity of S aSc. Similarly for c > aLb. 

< represents a and is ^—smooth: Let a G A — fi(A). By (/i0), 3b G /i(^4), so bRa, but (by above argument) not aRb, so bSa, but 
not aSb, so b < a, so a G A — fi < (A), and, as b will then be < —minimal (see the next sentence), < is y~ smooth. Let a G n(A), 
then for all a' G A aRa', so aSa', so there is no a' G A a' < a, so a G [i < (A). 
□ 
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